Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
|
 |
Access Control: Policies, Models, and Mechanisms
| |
|
Access Control: Policies, Models, and Mechanisms
Pierangela Samarati6 and Sabrina Capitani de Vimercati7 
| (6) |
Dipartimento di Tecnologie dell’Informazione, Università di Milano, Via Bramante 65, 26013 Crema (CR), Italy |
| (7) |
Dip. di Elettronica per l’Automazione, Università di Brescia, Via Branze 38, 25123 Brescia, Italy |
Abstract
Access control is the process of mediating every request to resources and data maintained by a system and determining whether
the request should be granted or denied. The access control decision is enforced by a mechanism implementing regulations established
by a security policy. Different access control policies can be applied, corresponding to different criteria for defining what
should, and what should not, be allowed, and, in some sense, to different definitions of what ensuring security means. In
this chapter we investigate the basic concepts behind access control design and enforcement, and point out different security
requirements that may need to be taken into consideration. We discuss several access control policies, and models formalizing
them, that have been proposed in the literature or that are currently under investigation.
Fulltext Preview (Small, Large)
 References secured to subscribers.
|
|
|
|
|
|